On May 25, 2016, EU member states adopted the General Data Protection Regulation (commonly referred to as GDPR), which revolutionizes existing regulations. The GDPR introduces many significant changes and innovations that affect both entrepreneurs and society. The new Regulation will harmonize data protection law across the entire European Union.
In Poland, in July 2016, the process of registering so-called prepaid SIM cards began. This obligation was imposed on telecommunications operators by the Anti-Terrorism Act. It sparked considerable controversy in society, primarily concerning their right to privacy. It did not significantly raise the level of citizen security, but rather led to a competition for customers among telecommunications operators.
Receive a package of free GDPR guides and micro-trainings
It is also noteworthy that the Court of Justice stated that an IP address is personal data and defined new legal frameworks for the transfer of personal data from the EU to the USA, namely the Privacy Shield decision. The attempt to replace the non-functioning Safe Harbour mechanism with a new self-regulation mechanism for entities located in the USA again ended in failure, as the proposed solutions do not provide an adequate level of security for data, which is confirmed by the opinions of both supervisory authorities and companies from third countries.
Leaks, leaks, leaks
Last year, many data thefts came to light. Companies such as Dropbox and the American portal Yahoo admitted to breaches from several years ago. There was also much talk about the database of user passwords from the MySpace portal that was made available by hackers. The popular LinkedIn also fell victim to user data theft.
The public opinion in our country was stirred in August by the mass collection of data by bailiffs from the PESEL system, which was described as a “leak.” The data concerned not only the debtors listed in the register but also their spouses and parents. This event caused financial and reputational losses for many individuals. The abuse of powers by those who have access to data raised doubts about the security of a significant part of the process of executing court judgments. Following the incident, the Inspector General for Personal Data Protection (GIODO) decided to conduct thorough verification activities regarding court bailiffs.
The Dangerous Side of Applications and Social Media
The applications Pokemon Go and Prisma drew public attention to the terms of use of software on mobile devices. The interest associated with them led to increased discussions about the reckless sharing of personal data and its consequences.
In June 2016, there was a phishing attack on Facebook. Within two days, the computers of over 10,000 users of the portal were infected.
In summary, the year 2016 was very important for personal data protection due to the emergence of new regulations revolutionizing the right to privacy within the EU. Additionally, through a series of incidents related to personal data, individuals using information society services became aware that there is also a darker side to disclosing their personal data. The most significant success of the past year is that entities began to adjust their actions to avoid violating the privacy rights of their clients, stakeholders, and also employees.


